Hacker Entertainment for COVID-19 Times

We are facing an extraordinary and very serious situation, so it is necessary for the population to stay at home. Fortunately we live in the information age and many of us hackers are used to being locked up at home since we were teenagers.

In this post I want to propose some hacker-themed ideas to train you and have a good time during confinement and all for free (or almost).

Update: More links and new sections including computer programing, lockpicking and web security.

Makers

Exploit Development and Reverse Engineering

Radio frequency (things you can learn even if you don’t have radios or SDR)

Hacking Challenges: Capture The Flag (CTF)

Web Security

Lockpicking

Computer Programming

Online Training (so many options but I put some interesting ones)

Videos

Books & Zines

I hope you find it useful and your confinement will be more pleasant. With all this material you will be busy for weeks, even months!

#StayAtHome / #StayAtHomeSaveLives

Reader: any proposal to add to this list? Thanks!

@simonroses

Posted in Pentest, Security, Technology, Uncategorized | Tagged , , , , , | Leave a comment

October, European Cyber Security Month 2018: Success or Failure?

Last October was the European Cyber Security Month 2018, an campaign aiming at increasing cyber security awareness across EU citizens promoted by ENISA (European Union Agency for Network and Information Security), each October for the last 5 years. Kudos ENISA.

In this post I take a look on the major security incidents/impacts that did happen in October alone (not counting vulnerabilities, exploits, etc.) I will only focus on breaches, malware, Nation-State attacks and other big incidents (on a side note, I’m including one vulnerability due to its high impact). Certainly, October has been a really interesting month for cyber security.

Please take a look on the following table divided into weeks:

Week (October 2018) Security Incident
1
  • Facebook Breach (50M users affected)
  • Russian spies (GRU cyber operatives) arrested in Netherlands
  • China Backdoor chips in USA
  • 2
  • Google+ Shutdown Due to Security Bug
  • US Pentagon Travel Records Breach
  • 3
  • Branch.io Flaw (685 million users affected)
  • Russian Cyber Vigilante
  • 8 Adult website Breach
  • 4
  • Cathay Pacific breach (9.4M users affected)
  • British Airways Breach (185K users affected)
  • 5
  • Nothing? (that we know of) ;)
  • Wow, some of these security incidents have got a lot of media coverage such as the Russians Spies, China backdoor chip in the USA and airlines breaches, just to mention a few. All these security incidents were published in October, crazy!

    Chances are I have missed some big security incident that happened in October, so if I’m missing something, please let me know to update post, thanks!

    I think cyber security is improving a little bit every year, but it’s clear much more work needs to be done! Less talk and more action (resource investment) is what cybersecurity really needs.

    So the question remains: is cyber security awareness improving or not? What do you think?

    SRF

    Posted in Privacy, Security, Technology, Uncategorized | Tagged , , , | Leave a comment

    Book Review: PoC||GTFO

    Yes, I’m back to blogging and doing a book review. I guess better late than never :)

    This time I’m reviewing the holy hacker book: International Journal of Proof-of-Concept or Get The Fuck Out (PoC||GTFO, ISBN-13: 978-1-59327-880-9). The book sums the best articles from hacker magazine PoC||GTFO, so you can read the journal for free. But I still recommend that you buy a copy of the holy book. The publisher, No Starch Press, even allows you to copy articles from the book to distribute digitally.

    pocpic

    Let me get to the point: if you are into exploit development, reversing engineering, radio hacking, software backdoor or hardware hacking, this is your book. Honestly any InfoSec Pro should read it.

    The book with a look&feel of the Bible is divided into 8 chapters, and each chapter has several high technical verses on different topics. Depending on your interest you will prefer some verses versus others, as I do, but I recommend reading the entire book, all 772 pages.

    My preferred verses are related to polyglot files, OS exploitation, radio hacking, software backdoors and Linux tricks.

    Some of my tops verses:

  • 1:4 Making a Multi-Windows PE
  • 1:5 This ZIP is also a PDF
  • 2:8 This OS is also a PDF
  • 3:10 Tales of Python’s Encoding
  • 4:3 This OS is a Boot Sector
  • 5:5 A Flash PDF Polyglot
  • 8:3 Compiler Bug Backdoors
  • 8:7 Stegosploit
  • 8:11 Naughty Signals


  • So go ahead, get yourself a copy now, read it and spread the word of the Lord ;)

    Kudos to the authors of Poc||GTFO, editors and all those involved with the magazine and book. Keep the words coming, neighbor!

    What are your preferred verses of the Holy Book?

    Score (1 rose, very bad / 5 roses, very good): 5 Roses (Must read)

    — Simon Roses Femerling / @simonroses

    Posted in Books, Pentest, Privacy, Security, Technology | Tagged , , , , , | 2 Comments